Libxml2

Vendor:

First CVE: Dec 31, 2003 · Active for 22 years

108
Total CVEs
More Total CVEs than 99% of tracked products
4.9
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Libxml2 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2003
22 years ago
Most Recent CVE
Jun 29, 2026
26 days ago

CVE Severity & Scoring

Libxml2108 CVEs
All CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local18 (16.7%)
Network63 (58.3%)
Unknown27 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low74 (68.5%)
High7 (6.5%)
Unknown27 (25.0%)
User Interaction
None48 (44.4%)
Unknown27 (25.0%)
Required33 (30.6%)
Privileges Required
Low4 (3.7%)
High0 (0.0%)
None77 (71.3%)
Unknown27 (25.0%)

Top CVEs

Signals from CVEs in this product scope (108 CVEs).

108 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-dependent attackers to cause a denial of service (crash) or ex
Sep 12, 200810.054NOYES
Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is no
Mar 1, 200510.049NOYES
Integer overflow in xpath.c in libxml2 2.6.x through 2.6.32 and 2.7.x through 2.7.8, and libxml 1.8.16 and earlier, allows context-dependent attackers to cause a denial of service
Sep 2, 20119.347NOYES
Buffer overflow in libxml2 allows remote attackers to execute arbitrary code by leveraging an incorrect limit for port values when handling redirects.
Feb 19, 20189.844NONO
Buffer overflow in the (1) nanohttp or (2) nanoftp modules in XMLSoft Libxml 2 (Libxml2) 2.6.0 through 2.6.5 allow remote attackers to execute arbitrary code via a long URL.
Mar 15, 20047.544NOYES
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML inp
Jun 22, 20269.840NONO
An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser option enabled, several integer counters can overflow. T
Nov 23, 20227.538NONO
xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in
Sep 25, 20169.837NONO
libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-siz
Jun 29, 20267.836NONO
The xmlParseElementDecl function in parser.c in libxml2 before 2.9.4 allows context-dependent attackers to cause a denial of service (heap-based buffer underread and application cr
Jun 9, 20167.535NONO

Exploit Exposure

Signals from CVEs in this product scope (108 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
6.5% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (108 CVEs).

Media Mentions

Signals from CVEs in this product scope (108 CVEs).

Top CNAs Publishing CVEs For Libxml2

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.9.825.93.4%00
2.9.477.93.4%00
2.9.327.54.8%00
2.9.225.53.9%00
2.9.1037.25.2%00
2.9.112.63.2%00
2.9.056.03.8%00
2.8.035.64.1%00
2.7.856.15.7%01
2.7.776.05.2%01
2.7.676.05.2%01
2.7.576.05.2%01
2.7.476.05.2%01
2.7.376.05.2%01
2.7.276.05.2%01
2.7.185.95.6%02
2.7.085.95.6%02
2.6.986.57.2%02
2.6.886.57.2%02
2.6.786.57.2%02